NAT/Portforward VIPs block
-
You shouldn't need any rules on WAN to allow traffic out from the VLAN6 subnet.
Try to ping out from Diag > Ping choosing the VLAN6 interface as the source address.
It sounds like maybe your ISP is not actually routing that subnet to your WAN IP.
Steve
-
I cant ping from that interface. this is what the ISP sent to me
set routing-options static route 65.15X.XXX.X44/29 next-hop 67.1XX.XXX.198
set routing-options static route 63.23X.XXX.X76/28 next-hop 67.1XX.XXX.198
So I used the /29 for the WAN and the /28 for VLAN6
-
So they directly attached it to you... Not routed it..
-
Ok knowing that now. How would I go about configuring the IPs then?
-
Get them to actually route it to you... Or you would have to use vips and port forwarding.
They are also having you set gateways outside the IP block... Not very good idea to be honest as well.
-
If i were to use VIP and port forwards would I have to port forward any devices they use on the network or can you they do that through there firewall? Also with the portforward what IP would be used for the gateway?
-
@johnpoz
Could I just assign another nic interface for that second IP block? then Have the VLAN go to that? -
No. The ISP should route 63.23X.XXX.X76/28 to an address in 65.15X.XXX.X44/29. They should provision your service properly.
-
Thank you all for your help. I got the ISP to route the IPs and it worked how you all explained it.
-
Nice.